Skip to content
HashiCorpCVE-2026-14869

HashiCorp Tooling: server-side request forgery

High8.6CVE-2026-14869 · Published Jul 28, 2026 · updated Jul 30, 2026

The terraform-mcp-server before version 1.1.0 is vulnerable to a server-side request forgery issue in the streamable-HTTP transport that may allow an unauthenticated remote client to redirect the server's Terraform API requests, and the server-side authorization token, to an attacker-controlled endpoint. This vulnerability, CVE-2026-14869, is fixed in terraform-mcp-server 1.1.0.

HashiCorp advisory

Affected versions

PackageAffectedFixed in
Tooling
Product
>= 0.3.0, < 1.1.01.1.0
Details and references

More HashiCorp advisories

All HashiCorp
Advisory
HashiCorp Consul: denial of service
Medium5.3Aug 7
Consul Community Edition and Consul Enterprise 1.20.1 through 2.0.2 are...
Medium4.2Aug 7
HashiCorp Tooling: server-side request forgery
High8.6Jul 29
In consul-mcp-server
Critical10.0Jul 29
The terraform-mcp-server before version 1.1.0 is vulnerable to a cross-tenant...
Critical10.0Jul 28
HashiCorp Tooling: session fixation
High8.9Jul 28

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.